Tech

Cisco patches critical security issues, so update now

Share
Share


  • Cisco releases fix for two flaws in Identity Services Engine
  • The flaws allowed for remote code execution, sensitive data exfiltration, and more
  • The first clean version of Identity Services Engine is 3.4

Cisco has released patches for two critical-severity vulnerabilities plaguing its Identity Services Engine (ISE) solution. Since the flaws can be abused to run arbitrary commands and steal sensitive information, Cisco urged its users to apply the fixes as soon as possible.

In a security advisory, the networking giant first said it patched a “deserialization of user-supplied Java byte streams” vulnerability tracked as CVE-2025-20124, and given a severity score of 9.9/10 (critical). By sending a custom serialized Java object to an affected Cisco ISE API, an attacker could execute arbitrary commands and elevate privileges.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Amazon says it expects to cut human workers and replace them with AI
Tech

Amazon says it expects to cut human workers and replace them with AI

Amazon CEO Andy Jassy urges workers to be “curious about AI” It...

This leaked Insta360 camera could be the Go 4 – and the design has me asking questions
Tech

This leaked Insta360 camera could be the Go 4 – and the design has me asking questions

Leaked image shows a rounded square design and a large lens Hints...

Microsoft working on next-gen Xbox video game console
Tech

Microsoft working on next-gen Xbox video game console

Credit: CC0 Public Domain Xbox president Sarah Bond on Tuesday confirmed that...